Dashboards & Visualizations

How to create a bar chart for dashboard displaying count on 1st of every month for past year?

rk1165
Loves-to-Learn Lots

I want to create a bar plot which displays the total number of events on the 1st of every month for the last 12 months. I can't query data for the last 12 months because search timeouts in 5 minutes as we have billions of events.

Is there a way we can do this using timechart or other mechanism?

Thanks

Labels (2)
0 Karma

smurf
Communicator

If you are looking only for the total number of events, you could use tstats. Searching through metadata tends to be quite fast, but could still time-out.

Another possibility would be using summaries. You could schedule a search to run every day/week/month to run for the specific period and have the visualization search run on the summary data.

You can find more about summary indexing here: Use summary indexing for increased search efficiency - Splunk Documentation

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could try using metasearch if all you want is counts based on a restricted set of fields

metasearch - Splunk Documentation

You could also restrict your time period to the first of every month

index ... (earliest=-12mon@d latest=-12mon@d+1d) OR (earliest=-11mon@d latest=-11mon@d+1d) OR ...

 You could create summary index entries for each month and query those.

0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...